FinAUTO Privacy Policy
FinAUTO | https://www.myfinauto.com
This Privacy Policy explains how FinAUTO (“FinAUTO,” “we,” “us,” or “our”) handles information in connection with the FinAUTO application, website, support channels, and related services (collectively, the “Services”). FinAUTO is operated by an individual developer based in Canada and is not represented in this Policy as an incorporated company or financial institution.
Table of Contents
Scope and Important Role Distinction
FinAUTO is software for managing vehicle-finance and related business records. It is not a bank, lender, NBFC, financial institution, financial adviser, credit bureau, or government authority.
Where an organization uses FinAUTO to manage its customers’ records, the organization generally determines why and how those customer records are collected and used. FinAUTO may process those records as a service provider or processor for the organization. FinAUTO may also act independently for account administration, billing, security, service analytics, legal compliance, support, and other purposes described in this Policy. The applicable role depends on the activity, the parties, the law, and the actual service arrangement.
Information We May Collect
How We Use Information
- Provide, maintain, secure, troubleshoot, and improve the Services.
- Create and manage accounts, organizations, offices, roles, permissions, devices, and subscriptions.
- Support synchronization, backups, document handling, exports, notifications, and other requested functions where available.
- Process billing, trial status, renewals, cancellations, refunds, and payment-related support.
- Detect, investigate, prevent, and respond to fraud, abuse, unauthorized access, security incidents, and technical problems.
- Provide customer support, communicate service information, and respond to privacy or legal requests.
- Meet legal, regulatory, contractual, accounting, audit, dispute-resolution, and enforcement obligations.
- Use technical and anonymized or aggregated information for service operation, analysis, and improvement. We do not use identifiable customer records, KYC documents, or uploaded files for unrelated purposes without an appropriate legal basis and disclosure.
Organization-Managed Customer Data
Organizations are responsible for ensuring that they have the authority, lawful basis, notices, permissions, consents, and other approvals required to collect, upload, access, use, disclose, and retain information in FinAUTO. Organizations are responsible for configuring roles and permissions and ensuring that staff access only information necessary for their duties.
FinAUTO may rely on instructions from authorized organization administrators, subject to security controls, applicable law, and the actual service arrangement. Internal disputes between owners, administrators, staff members, customers, or other parties must generally be resolved by the organization or relevant parties. FinAUTO may restrict or suspend disputed access where reasonably necessary for security, legal compliance, or protection of information.
Legal Bases and Permissions
Depending on the jurisdiction and activity, we may rely on consent, performance of a contract, legitimate operational purposes, legal obligations, security purposes, or another basis permitted by applicable law. Consent is not assumed merely because information is technically submitted; where a specific consent or notice is legally required, the responsible party must provide it.
Sharing and Service Providers
We may disclose information to service providers and other parties where reasonably necessary for the Services or permitted by law. Categories may include cloud/database hosting, file and image storage, authentication and security, payment processing, email and communications, error monitoring, analytics, support tools, professional advisers, insurance providers or brokers where applicable, and legal or governmental authorities.
Service providers may process information in countries other than the country where it was collected. We prefer India as a primary hosting region for the India-focused service, subject to actual infrastructure availability and verification. We do not promise that all data, backups, logs, or support information will remain exclusively in India.
International Transfers
Information may be processed or stored in Canada, India, or other countries where FinAUTO or its service providers operate. Where required, we will use safeguards and transfer mechanisms appropriate to the applicable law and circumstances. The protections available in another country may differ from those in your home jurisdiction.
Retention and Deletion
Organizations control retention of their business records, subject to the organization’s legal duties, contractual commitments, and available FinAUTO features. FinAUTO separately determines retention periods for account, billing, security, audit, support, legal, dispute, and backup records based on purpose, risk, operational needs, and applicable law.
Deletion requests may require identity or authority verification. Deletion may not immediately remove every copy from backups, security logs, audit records, legal holds, dispute files, or systems that cannot be promptly altered. Eligible data may be deleted under inactive-account, suspension, retention, or legal policies after appropriate notice where practical.
Your Requests and Privacy Rights
Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about processing. Rights may be limited by law and may differ when FinAUTO is processing information for an organization that controls the relevant records.
Submit privacy requests to privacy@myfinauto.com. Organization-managed requests may also need to be submitted through the relevant organization administrator. We may request information needed to verify identity, authority, scope, and security. We aim to respond within approximately 30 days where practical, while statutory deadlines and complexity may apply.
Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature and sensitivity of information, including role-based access controls, authentication controls, logging, access restrictions, transmission encryption (such as HTTPS/TLS), and secure storage controls where implemented. FinAUTO operates as a cloud-hosted software tool and does not provide client-side device-level encryption or zero-knowledge key isolation; organizations and users remain solely responsible for the physical security, credential confidentiality, and operating system protection of their individual Android devices, PINs, locks, and pairing codes. No method of electronic transmission or technical storage is completely secure, and absolute security cannot be guaranteed.
Security Incidents
We will investigate, contain, and address suspected security incidents and assess applicable legal and contractual notification duties. We may notify affected individuals, organizations, regulators, or other parties where required or appropriate, subject to the facts, law, security considerations, and available contact information.
Children and Minimum Age
The Services are intended for businesses and adults. We do not intentionally permit minors to independently create or use accounts. Any exception involving a parent or guardian is subject to legal assessment and implementation.
Cookies, Analytics, and Diagnostics
Depending on the actual website and application technology used, FinAUTO may use essential technologies and, where implemented, optional analytics or marketing technologies. Controls or consent mechanisms will be provided where required. Crash and diagnostic information is intended to support reliability and security and should exclude unnecessary personal information, customer records, KYC documents, and uploaded files.
Policy Updates
We may update this Policy as the Services, providers, laws, or practices change. The current version may be made available through the application and website. We may provide in-app notice and request renewed acknowledgment or acceptance for material changes where legally or contractually required. The effective date will be updated when changes take effect.
Contact and Privacy Officer
Under applicable privacy laws (including Quebec Law 25), the person exercising the highest authority within FinAUTO acts as the Person in Charge of the Protection of Personal Information (Privacy Officer). For inquiries, privacy requests, or complaints, contact:
Questions About Data Boundaries or Privacy?
Our team is available to assist with your privacy inquiries and operational questions.